Paste a suspicious text, email or DM and find out whether it matches a known scam script, with every link checked.
The message is analysed entirely in your browser. Nothing you paste is sent to our server, and no link inside it is opened.
Most scams now start with a short message rather than a phone call. A text says a parcel is held, a toll is unpaid or a bank card has been locked. A WhatsApp from an unknown number says it is your son on a new phone. An email says your subscription renewed and you need to call to cancel. The wording is written to make you act before you think, and on a small screen it can look exactly like the real thing.
This checker reads the message the way a fraud analyst would. It looks for the building blocks scammers reuse in every campaign: pressure and deadlines, threats of fines or suspension, requests for gift cards, crypto or one time codes, secrecy, and impersonation of delivery companies, toll operators, banks, tax offices and family members. It pulls out every link and phone number, runs each link through the same analysis as our phishing link checker, and tells you which known scam script the message most closely matches and what to do about it.
Nothing is uploaded. The analysis runs on your own device, so you can safely paste a message that contains your name, address or account details.
Message scams are now one of the most costly routes for fraud. The US Federal Trade Commission reported that people lost 470 million dollars to scams that started with a text message in 2024, five times the figure for 2020, and it names fake delivery problems, bogus job offers, fake bank fraud alerts, unpaid toll demands and wrong number openers as the most reported types. In Australia, the National Anti-Scam Centre reported 2.03 billion dollars lost to scams in 2024, with investment scams, romance scams, payment redirection and remote access scams causing the largest losses. Most of those scams began with a message.
The scripts are industrialised. Criminal groups buy ready made phishing kits that copy the look of a postal service, toll operator or bank, then send hundreds of thousands of near identical texts. The small fee in a delivery or toll text is not the goal. It collects your full card number and security code, which are then used for much larger purchases or added to a digital wallet with a one time code the scammer tricks you into reading out.
Family impersonation scams, often called Hi Mum or Hi Dad scams, skip links altogether. The sender claims to be a child who lost their phone, moves the conversation to WhatsApp, and asks for an urgent transfer for a bill they cannot pay from their new account. The request to keep it quiet from the other parent is deliberate, because a single phone call to the real child ends the scam.
Job, investment and romance scams play a longer game. The first message is friendly and asks for nothing. Over days or weeks the conversation moves to a messaging app, trust is built, and money is requested only once the victim is invested. Checking the first message catches the opener, and checking later messages catches the moment the request for money arrives.
Look for the combination scammers rely on: an unexpected message, pressure to act quickly, and a link, phone number or payment request. Genuine organisations rarely ask you to pay a fee, confirm card details or share a code through a link in a text. If the message claims to be from a company you use, ignore the link and open the company's app or type its website address yourself.
Replying, even with STOP, confirms your number is active and read by a real person, which often leads to more scam messages. It rarely causes direct harm on its own. If you replied with personal details, a code or a payment, contact your bank straight away and change the password for any account you mentioned.
If you only opened the page and entered nothing, close it and delete the message. If you entered card details, call your bank on the number on the back of your card and ask for the card to be cancelled. If you entered a password, change it on the real site and anywhere you reused it, then turn on two factor authentication. If you installed an app, uninstall it and run a security scan.
In the UK and the US you can forward scam texts free to 7726, which spells SPAM on a keypad. In Australia, Telstra customers can forward scam texts to 7226, and anyone can report to Scamwatch. In the US you can also report to ReportFraud.ftc.gov, in England, Wales and Northern Ireland to Report Fraud, and in Canada to the Canadian Anti-Fraud Centre.
Do not reply to the new number. Call or video call your child on the number you already have saved, or ask another family member to reach them. You can also ask a question only your child would know the answer to. A genuine child with a broken phone will understand. A scammer will make excuses about why they cannot talk.
Yes. Sender names on text messages can be spoofed, so a scam text can appear in the same conversation as genuine messages from your bank or delivery company. Email display names can also be faked. That is why the content of the message and where its links lead matter more than the name it shows.
Yes. The checker runs in your browser and does not send the message to our server or anyone else. If you prefer, you can replace your name, address or account number with placeholder text before you paste. The result will be the same.